
Keap
Based exclusively on public evidence • 20 criteria (Privacy + AI)
Last review: 21 Feb 2026

AI Trust Summary
- •Regarding AI: it does not document ethical principles and anti-bias measures, which may affect trust in automated marketing campaigns.
- •Regarding Core Privacy: it does not inform about data retention periods, creating uncertainties about customer information management.
Safer Alternatives
Higher-rated software in the same category
Attention Points in AI (1)
AI criteria that require attention. Buy the Premium Analysis to see all 1 criteria.
- •Keap
- •Omission of ethical AI principles may compromise customer trust in campaigns.
- •Does not specify data retention periods, which creates uncertainties about information management.
- •It is advisable to require contractual clauses that address these aspects.
Ethical AI principles and anti-bias measures not documented
The lack of ethical commitments in AI can negatively impact customer trust in automated marketing campaigns.
Source: vendor public documents
Compliances in AI (3)
AI criteria the company meets. Buy the Premium Analysis to see all 3 criteria.
- •Keap
- •Clearly documents the use of AI in its functionalities, such as 'Chatbot Technology' and 'Profiling'.
- •Defines data controller and processor roles, ensuring transparency in marketing practices.
- •These practices facilitate due diligence and strengthen customer trust.
AI data retention policy clearly documented
Lack of clarity on the retention period for Chatbot interaction data can affect customer trust in automated campaigns.
Policy on data use for AI training clearly stated
The policy mentions the use of customer data to improve services, but is not clear about its use for training AI models.
AI training opt-out control available
The policy offers generic controls, but there is no specific opt-out for the use of data in AI training.
Source: vendor public documents
Highlights in Privacy (3)
Most relevant criteria for this category. Buy the Premium Analysis to see all 3 criteria.
Data retention period not stated in the policy
The absence of clear deadlines for customer data retention can create uncertainties about information management in marketing campaigns.
Performance of contract legal basis applied to essential data
The policy mentions the use of data to fulfill the reason it was provided, but does not explicitly cite the legal basis.
Data controller and processor roles clearly defined
Clear identification of data controller and processor roles is fundamental for compliance in marketing practices.
Source: vendor public documents
Critical Alerts
- •Período de retenção de dados não informado na política: Definir prazos de retenção é essencial para a transparência e conformidade na automação de marketing..
- •Legítimo interesse com balanceamento de direitos claramente explicado: Explicar o balanceamento de direitos é fundamental para a transparência nas práticas de marketing.
Conformance analysis (20)
Ethical AI principles and anti-bias measures not documented
Reference: ISO/IEC 42001 (6.1) + ISO/IEC TR 24028 + EU AI Act (Art. 9)
Data retention period not informed in the policy
Reference: ISO/IEC 27701 (7.4.6)
Clearly documented AI data retention policy
Reference: ISO/IEC 42001 (8.2) + ISO/IEC 27701 (7.4.6)
Source: vendor public documents
Follow this company and access all 20 criteria
Track score changes, get alerts on policy updates, and view the full conformance analysis
Don't miss any update
Sign up to follow this company and track changes in privacy and AI scores
Why trust the AITS Index: Open Community Audit
Public transparency, peer review and open evidence trails — all verifiable by the community
Trust guarantees
Peer review
users, professionals and experts confirm or contest items online.
Public history
vendor and index changes are versioned and accessible.
Participate
Evidence, confirmations and contestations
participate in the collaborative validation of AITS criteria
Understanding Keap's Privacy and AI Governance: Strengths, Weaknesses, and Practical Guidance
Privacy Strength: Clear AI Usage Policies
Keap excels in transparency regarding its use of artificial intelligence in marketing automation. The platform provides clear documentation on how AI is utilized, which is crucial for users who want to understand the implications of automated marketing on their campaigns. This clarity helps users make informed decisions about their marketing strategies and ensures compliance with regulations like GDPR and LGPD, which emphasize the importance of transparency in data processing. Users can feel more confident knowing that Keap openly communicates its AI practices, allowing them to align their marketing efforts with ethical standards.
Privacy Strength: Defined Roles of Data Controller and Processor
Another strength of Keap is its clear delineation of roles between data controllers and processors. This distinction is vital for users, as it clarifies who is responsible for data management and compliance. By understanding these roles, users can better navigate their obligations under privacy laws such as ISO 27701. This clarity not only fosters trust but also aids users in ensuring that they are meeting their legal responsibilities regarding data protection. Users should regularly review these roles in their settings to ensure they are correctly configured for their specific use cases.
Privacy Weakness: Lack of Ethical AI Principles
Despite its strengths, Keap has notable weaknesses, particularly concerning its documentation of ethical AI principles. The absence of clear guidelines on anti-bias measures can lead to potential risks in automated marketing campaigns. Users should be aware that without these principles, there is a risk of unintentional bias affecting their marketing outcomes. To mitigate this risk, users are encouraged to monitor their campaigns closely and consider implementing additional checks or balances to ensure fairness and inclusivity in their marketing strategies. Regular audits of campaign performance can help identify any unintended biases.
Privacy Weakness: Unclear Data Retention Period
Another significant concern is Keap's lack of information regarding data retention periods. Not knowing how long customer data is retained can create uncertainty and potential compliance issues under GDPR and LGPD. Users should take proactive steps to clarify this aspect with Keap’s support team. Additionally, users should implement their own data management policies that specify how long they will retain customer data and under what conditions it will be deleted. This practice not only enhances compliance but also builds trust with customers who are increasingly concerned about data privacy.
Practical Guidance: Settings to Check for Compliance
To ensure compliance and enhance privacy practices while using Keap, users should regularly review their account settings. This includes checking the data processing agreements and ensuring that the roles of data controllers and processors are correctly assigned. Users should also explore the AI settings to understand how automated decisions are made and consider disabling features that do not align with their ethical standards. Regularly updating privacy policies and communicating them to customers can also help maintain transparency and trust.
Practical Guidance: Alternatives and Precautions
For users concerned about the weaknesses identified, it may be beneficial to explore alternative marketing automation platforms that offer more robust ethical AI frameworks and clearer data retention policies. Additionally, users should consider implementing additional privacy tools or services that can complement Keap’s offerings, such as data encryption solutions or third-party compliance audits. By taking these precautions, users can better safeguard their marketing practices and ensure they are operating within the bounds of privacy regulations.
Other Marketing Automation software
Dive into in-depth research and analysis of each player
Source: vendor public documents
Analyzed Sources
Public documents used in the audit of Keap:
Evidence, confirmations and contestations
participate in the collaborative validation of AITS criteria
Scope & Limitations
TrustThis/AITS assessments are based exclusively on publicly available information, duly cited with date and URL, following the AITS methodology (privacy & AI transparency).
The content is indicative in nature, intended for screening and comparison, not replacing internal audits.
TrustThis/AITS does not perform invasive tests, does not access vendor technology environments and does not process customer personal data. Conclusions reflect only the vendor's public communication at the date of collection.
Source: vendor public documents






